Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14757

Опубликовано: 05 июл. 2026
Источник: redhat
CVSS3: 5.3

Описание

A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.

A flaw was found in radareorg radare2. A local attacker could exploit an integer overflow vulnerability within the core_anal_bytes function. This manipulation could lead to limited impacts on confidentiality, integrity, and availability of the system.

Отчет

This Moderate impact flaw in radare2 allows a local attacker to trigger an integer overflow within the core_anal_bytes function. Exploitation requires local access to the system and could lead to limited impacts on data confidentiality, integrity, and system availability.

Меры по смягчению последствий

To mitigate this issue, users should exercise caution when processing untrusted or maliciously crafted files with radare2. Avoid opening or analyzing files from unknown or unverified sources. Additionally, consider running radare2 within a sandboxed environment, such as a container or a restricted user account, to further limit the potential impact of exploitation.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2497164radare2: Radare2: Integer overflow allows local impact

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.

CVSS3: 5.3
nvd
около 1 месяца назад

A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.

CVSS3: 5.3
debian
около 1 месяца назад

A vulnerability was determined in radareorg radare2 up to 6.1.6. This ...

CVSS3: 5.3
github
около 1 месяца назад

A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.

5.3 Medium

CVSS3